MEDIUM6.1
PYSEC-2026-1357
FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function
Details
A cross-site scripting (XSS) vulnerability in the Config-Create function of fastapi-admin pro v0.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/fastapi-admin
Introduced in:
0No fixed version published yet for fastapi-admin (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-42818[ADVISORY]
- https://github.com/fastapi-admin/fastapi-admin/issues/172[WEB]
- https://fastapi-admin-pro.long2ice.io/admin/login[WEB]
- https://github.com/fastapi-admin/fastapi-admin[PACKAGE]
- https://pypi.org/project/fastapi-admin[PACKAGE]
- https://github.com/advisories/GHSA-grqx-r2q2-j425[ADVISORY]